Legal
Privacy policy
Last updated 1 October 2026
In short
- This website sets no cookies and uses no trackers.
- Our products collect only what they need, and we never sell personal data.
- Payments are handled by Stripe; we never see your full card number.
- You can ask us to access, correct, export or delete your data at any time.
Who we are
This policy explains how Pebblebit (“we”, “us”) handles personal data when you visit pebblebit.com, write to us or use one of the products listed on our products page. Where a product needs to tell you something specific, its website adds a short product notice that supplements this policy.
The controller of your personal data is Pebblebit. You can reach us about anything in this policy at hello@pebblebit.com.
This website
This website sets no cookies and uses no analytics, advertising or social media trackers. Our fonts are hosted on our own domain, so loading a page does not contact any third party.
The site is hosted by Cloudflare. To deliver pages and protect the site against abuse, Cloudflare processes technical data such as your IP address, browser type, the page requested and the time of the request. These logs are kept for a short period, usually no more than a few weeks, and are used only for security and reliability.
When you contact us
If you email us, we receive your email address, your name if you include it, and whatever you choose to write. We use this only to answer you and to keep a record of the conversation. We keep support conversations for up to two years after the last message, longer only if they relate to an order we must keep records of or a legal claim.
When you use our products
- Account and order details. Your email address, and your name if you give it, together with what you bought, when, and the status of any subscription. We need these to provide the product, send receipts and handle support.
- Payment details. Payments are processed by Stripe. We never see or store your full card number. Stripe shares limited details with us, such as the card brand, the last four digits, the expiry date and the billing country, so we can identify payments and handle refunds. Stripe’s own use of your data is described in the Stripe Privacy Policy.
- Content you provide. Files and text you submit to a product are processed only to produce the result you asked for. They are deleted within the period stated on that product’s website, and never kept longer than needed to deliver and support the result.
- AI processing. Some products send your input to an AI model provider to produce a result. We only use providers that process your content on our behalf and do not use it to train their models.
- Technical data. Minimal logs such as IP address, device and browser details, and error reports, used to keep the product secure, prevent fraud and fix problems.
- Advertising measurement on product websites. Some product websites use measurement tools, such as Google Ads conversion tracking, to learn which of our ads work. Where the law requires consent, for example in the EU and UK, these tools run only after you agree, and each product website explains its choices in its own cookie notice.
Google user data
Pebblebit is an application used internally by our team. It signs in with Google and uses the Google Ads API to access Google Ads accounts that belong to Pebblebit. It does not access the Google accounts of our customers or website visitors.
What the app accesses
- The Google account email address of the team member who authorises access, so we know who connected which account.
- Data in Pebblebit’s own Google Ads accounts: account structure, campaigns, ad groups, ads, keywords, budgets and bids, performance statistics such as impressions, clicks, costs and conversions, and planning forecasts.
How we use it
We use this data only to plan, create, manage and measure advertising for our own products, and to produce internal reports. We do not use it to target individuals, we do not sell it, and we do not use it to develop, improve or train generalised AI or machine learning models.
How we store and protect it
Access tokens are encrypted and stored on infrastructure that only our team can reach. Reporting data is kept for up to 24 months and then deleted. We share Google user data with no one, except infrastructure providers such as Cloudflare that host our systems on our instructions, or where the law requires it.
Revoking access and deletion
Access can be revoked at any time from the Google Account permissions page. When access is revoked we stop using the stored token, and on request to hello@pebblebit.com we delete any related data within 30 days.
Pebblebit’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Legal bases
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases:
- Contract: to provide a product you asked for, process payments and give support.
- Legitimate interests: to keep our services secure, prevent fraud, understand and improve our products, and advertise our own products. We balance these interests against your rights, and you can object at any time.
- Consent: for optional cookies and advertising measurement on product websites, and for any marketing email. You can withdraw consent at any time.
- Legal obligation: to keep order and accounting records for as long as the law requires.
International transfers
We and our providers process data in the United States and other countries. When personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the EU–U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses and their UK equivalents.
How long we keep data
| Data | How long |
|---|---|
| Website security logs | A few weeks at most |
| Content you submit to a product | As stated on the product’s website, then deleted |
| Account details | While your account is active, deleted within 30 days after you close it |
| Order and invoice records | As long as accounting law requires, up to 10 years |
| Support conversations | Up to 2 years after the last message |
| Google Ads reporting data | Up to 24 months; tokens until access is revoked |
Your rights
Depending on where you live, you can ask us to access, correct, export or delete your personal data, to restrict or object to how we use it, and to withdraw consent you have given. California residents also have the right to know what we collect, to opt out of sale or sharing, and not to be treated differently for using these rights.
To make a request, email hello@pebblebit.com. We may need to confirm your identity first. We reply within one month, or within the period your local law sets. If you are in the EEA or UK, you can also complain to your local data protection authority.
Children
Our products are not made for children and are not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
Security
All our websites use HTTPS. We encrypt sensitive data, limit access to the people who need it and review what our providers do with data. No system is perfectly secure, so if you find a weakness, please report it to hello@pebblebit.com.
Changes to this policy
When we change this policy we update the date at the top. If a change is significant, we tell affected customers by email or with a notice on the relevant product before it takes effect.